Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor.
54
61%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/sidewinder/SKILL.mdSideWinder (MITRE ATT&CK G0121) is a suspected Indian state-sponsored cyber-espionage group active since at least 2012. It is one of the most prolific APT actors in the South Asian threat landscape, with over 1,000 documented attacks against government organizations in the Asia-Pacific region since April 2020 alone. SideWinder is characterized by rapid malware iteration (generating modified variants in under five hours after detection), heavy reliance on spearphishing with government/military-themed lures, exploitation of the aged CVE-2017-11882 Equation Editor vulnerability, multi-stage JavaScript and .NET infection chains, and custom post-exploitation tooling — most notably the modular StealerBot implant discovered in 2024. The group maintains a massive infrastructure footprint (400+ live domains with hundreds of sub-domains mimicking legitimate government sites) and has progressively expanded from its traditional Pakistan-centric targeting to maritime, logistics, nuclear, and diplomatic entities across the Middle East, Africa, and Southeast Asia.
mshta.exe used to execute malicious HTA payloads containing JavaScript, a signature SideWinder technique.rekeywiz.exe) hijacked to side-load malicious DLLs — a signature SideWinder persistence and evasion technique.rekeywiz.exe); WarHawk masquerades as ASUS Update Setup and Realtek HD Audio Manager.mshta.exe to run unsigned HTA/JavaScript payloads.mstsc.exe processes, and captures keystrokes. (Not yet assigned individual ATT&CK technique IDs for all modules, but aligns with T1555.003, T1056.001, T1557-adjacent RDP interception.)mstsc.exe creation events.winmgmts:\.\root\SecurityCenter2 to enumerate installed antivirus products.mofa-gov-sa.direct888[.]net), disguising malicious traffic as legitimate.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| StealerBot | (no ATT&CK software ID assigned) | Modular memory-only post-exploitation framework (Orchestrator + modules for screencap, keylog, credential theft, file exfil, RDP interception) | Custom |
| WarHawk | (no ATT&CK software ID assigned) | Backdoor with Cobalt Strike loader, command execution, file manager, upload modules; validates PKT timezone | Custom |
| SideWinder.AntiBot.Script | (no ATT&CK software ID assigned) | Server-side phishing evasion script filtering non-target visitors | Custom |
| ModuleInstaller | (no ATT&CK software ID assigned) | .NET downloader / second-stage loader for StealerBot | Custom |
| Custom JavaScript downloaders | (no ATT&CK software ID assigned) | Multi-stage JS loaders executed via HTA/mshta, fetching .NET payloads | Custom |
| Custom LNK loaders | (no ATT&CK software ID assigned) | Weaponized shortcut files initiating the infection chain | Custom |
| Koadic | S0250 | Post-exploitation framework (COM-based) | Public |
| Cobalt Strike | S0154 | Post-exploitation framework (deployed via WarHawk) | Public (commercial) |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. SideWinder's techniques are designed for stealth and persistence — ensure all implant infrastructure is properly scoped and can be decommissioned cleanly.
Map SideWinder's signature plays to Decepticon's own capabilities:
mofa-gov-[cc].domain[.]net).mshta.exe to execute an HTA containing JavaScript; the JavaScript performs remote template injection to fetch an RTF exploiting CVE-2017-11882 (Equation Editor); the exploit launches additional JavaScript that downloads a .NET loader (ModuleInstaller analog). Use the payload-builder skill for each stage, keeping payloads as close to SideWinder's documented chain as possible.rekeywiz.exe) to side-load a malicious DLL. Ensure the final implant (StealerBot analog) loads modules only into memory — no disk artifacts for the post-exploitation payload. Apply base64 and ECDH-P256 (or equivalent asymmetric) encryption to all staged payloads.mstsc.exe to intercept RDP credentials via named pipes, and log keystrokes. Monitor for process creation events matching target process names.eqnedt32.exe); monitor for EQNEDT32.EXE spawning child processes — any child process is anomalous. This single CVE has been SideWinder's most persistent exploitation vector across all campaigns.mshta.exe execution with URL or file arguments, especially from user profile directories (Downloads, Desktop, Temp); alert on LNK files in email attachments and ZIP archives; watch for mshta.exe → wscript.exe / cscript.exe → powershell.exe process chains.rekeywiz.exe, credwiz.exe) executing from unusual paths (user %TEMP%, %APPDATA%); alert on DLL loads from non-standard directories by known side-loading targets; maintain a baseline of expected DLL paths for commonly abused binaries.mshta.exe, wscript.exe, and cscript.exe execution via AppLocker/WDAC; alert on script interpreters making outbound HTTP connections; monitor for base64-encoded content in script arguments.mstsc.exe; alert on creation of named pipes matching patterns used by StealerBot (e.g., static pipe names like c63hh148d7c9437caa0f5850256ad32c); monitor for anomalous RDP credential access patterns.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.